netVigilance Vulnerability intelligence since 2004

KEV in numbers

What the Known Exploited Vulnerabilities catalogue looks like as a dataset: 1,703 records as of 2026-09-09, computed directly from the data and recomputed twice a day. Every figure here can be reproduced from the public JSON.

1,703records tracked
283vendors
21%ransomware-linked
43%exploited within the CVE's first year
96CVEs 10+ years old at entry
21dmedian remediation window

Additions by year

2021–2022 include the catalogue's launch backlog, not fresh exploitation of those years

KEV additions by year with ransomware share
Year Added Share of catalogue Ransomware-linked
2021 311 18.3% 27%
2022 555 32.6% 24%
2023 187 11.0% 23%
2024 186 10.9% 24%
2025 245 14.4% 13%
2026 219 12.9% 11%

How old a CVE is when exploitation is confirmed

Catalogue year minus CVE identifier year — an assignment-year proxy, see the note below

Age of CVEs at the moment they enter KEV
Age at entry Records Share
Same year 739 43.4%
1 year 272 16.0%
2–4 years 323 19.0%
5–9 years 273 16.0%
10+ years 96 5.6%
The headline: 57% of confirmed exploitation targets a vulnerability older than the current year. Patching new CVEs is half the job; the other half is the backlog.

Old vulnerabilities, fresh exploitation

CVEs at least a decade old when CISA confirmed attacks, added since 2025

Decade-old CVEs recently added to KEV
CVE Vendor / product Age at entry Added
CVE-2007-0671 Microsoft / Office 18 years 2025-08-12
CVE-2008-0015 Microsoft / Windows 18 years 2026-02-17
CVE-2008-4128 Cisco / IOS 18 years 2026-07-13
CVE-2008-4250 Microsoft / Windows 18 years 2026-05-20
CVE-2009-0238 Microsoft / Office 17 years 2026-04-14
CVE-2009-0556 Microsoft / Office 17 years 2026-01-07
CVE-2009-1537 Microsoft / DirectX 17 years 2026-05-20
CVE-2009-3459 Adobe / Acrobat and Reader 17 years 2026-05-20

Vendors

All-time and the last 12 months (290 additions)

Vendors by number of KEV records
Vendor All time Share Last 12 months
Microsoft 388 22.8% 48
Cisco 97 5.7% 19
Apple 94 5.5% 10
Adobe 81 4.8% 7
Google 74 4.3% 10
Oracle 46 2.7% 7
Apache 40 2.3% 2
Ivanti 35 2.1% 5
Fortinet 30 1.8% 10
Linux 28 1.6% 6
D-Link 26 1.5% 2
VMware 26 1.5%
Citrix 24 1.4% 3
Synacor 19 1.1% 6
SonicWall 19 1.1% 5
Top 15 of 283 vendors · full per-vendor pages are linked from each row

Remediation windows

Days between a record entering KEV and its federal deadline

Distribution of remediation windows
Window Records Share
7 days or less 135 7.9%
8–21 days 1304 76.6%
22–90 days 7 0.4%
Over 90 days 257 15.1%
The 7-day windows are CISA's "act now" tier; the long tail over 90 days is mostly the catalogue's 2021 launch, which gave agencies six months for the historical backlog.

Method, honestly

Everything above is computed from the CISA KEV catalogue as of 2026-09-09. "Age at entry" uses the year embedded in the CVE identifier, which is the year the identifier was assigned — usually but not always the disclosure year, so treat single-year precision with care. Ransomware share reflects CISA's "known ransomware campaign use" flag, which is conservative: absence of the flag is not evidence of absence. Reproduce or extend any of this from the public JSON; if you publish something based on it, a link back is appreciated.